High severity8.8NVD Advisory· Published Apr 2, 2026· Updated Apr 7, 2026
CVE-2026-34794
CVE-2026-34794
Description
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.vulncheck.com/advisories/endian-firewall-cgi-bin-logs-ids-cgi-date-perl-command-injectionnvdThird Party Advisory
- help.endian.com/hc/en-us/sections/360004371358-CommunitynvdRelease Notes
News mentions
0No linked articles in our index yet.